发明授权
US07131140B1 Method for protecting a firewall load balancer from a denial of service attack
有权
保护防火墙负载平衡器免受拒绝服务攻击的方法
- 专利标题: Method for protecting a firewall load balancer from a denial of service attack
- 专利标题(中): 保护防火墙负载平衡器免受拒绝服务攻击的方法
-
申请号: US09788690申请日: 2001-02-19
-
公开(公告)号: US07131140B1公开(公告)日: 2006-10-31
- 发明人: Chris O'Rourke , Gaurang K Shah , Louis F Menditto , Mark Albert , Michael S Sutton , Pranav K Tiwari , Robert M Batz , Richard Gray , Sean W Hull , Tzu-Ming Tsang
- 申请人: Chris O'Rourke , Gaurang K Shah , Louis F Menditto , Mark Albert , Michael S Sutton , Pranav K Tiwari , Robert M Batz , Richard Gray , Sean W Hull , Tzu-Ming Tsang
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Baker Botts L.L.P.
- 主分类号: G06F9/00
- IPC分类号: G06F9/00
摘要:
A method for protecting firewall load balancers from a denial of service attack is provided. Packets are received by the firewall load balancer. Each packet has a source and a destination. The firewall load balancer is equipped with a connection database that can contain entries about the packets. Upon receipt of a packet, the connection database is queried to determine whether or not there is an entry for the received packet. If an entry is found in the database, the packet is forwarded to its destination. Otherwise, if the packet was received from a firewall, then a new connection entry for the packet is built and is saved to the connection database and the packet is forwarded on to its destination. If the packet does not have an entry (match) in the connection database and the packet was not received from a firewall, then the packet is forwarded to a firewall.
信息查询